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Notes for Dutch SIGENT/Cyber Analytic Exchange 
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L4 February 2013 

Organization of Cvber in the Netherlands (L T ) 

(S SI REL TO USA., NLD) Die meeting began with a briefing from the Dutch about 
their reorganization and t he creati on of the new SIGINT at id Cyber Division and Single 
Point of Contact (SPoC) noted that Ptoj to create this new division 

appears to be on track, with MEVD and AIVD technical specialists starting to be pulled 
out of their original locations to join the new division, located at AIVD HQ in 
Zoetermeer. This new division will be headed by a steering committee comprised of 
MIVD Director Pieter Bindt and. AIVD Director Rob Bertholee. Under them will be the 
SPoC. headed as a sidenote. plans are under way for^^| to visit 

NS A at die end of May . Slide 7 includes a couple of abbreviations: AS = MI VD : s 
SI GIXT Division, SOM — AIVD s Special Investigating Committee, QMO — the support 
organization. The SPoC technical specialists will work closely with the analysts 
(including branch), who will remain in AIVD outside the new entity. NLXCSA 

(the Dutch equivalent of lADjwili probably also be pulled into the new entity. 

(S SI REL TO USA, NLD) Die Dutch created the National Cyber Security Center 
(NCSC) in Jan 2012 to cov er general (not military) cyber issues, and this center is still 
dealing with growing pains It is having difficulty filling all its vacancies, it still lacks a 
legal framework, and private companies fight any public notification that cyber attacks 
have taken place When asked where to turn for help in the case of an intrusion on a 
commercial entity, the ans wer wa s that it depends — if the help needed is technical, then 
AIVD; otherwise, NCSC averred that AIVD has good relations with companies, 

Die national police (KLPD) has a liaison with NCSC also 

($. SI REL TO USA, NLD) Die National Detection Network (NDN> governs Dutch 
sensors. This network is DEVELOPING — some sensors are public and some are private, 
some entities have their and they tie into the NCSC | 
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(S- SI RELTO USA, NLD) Some other notes 

* The Dutch do not have red or blue teaming yet 

* AIVD is concerned with espionage, not crime 

* The Dutch are working toward having only one IP point where all government 
agencies touch the internet, because this will be easier to monitor defend 

* 80 percent of NSA tools used to find malware are commercial, while 100 percent 
of Dutch tools are 

* In the cyber realm, there is no ONE government agency in charge yet, but it will 
eventually be the NCSC 

* There is still no cable access yer ; but the laws may be changed in the next year or 
two. However, Dutch lawyers believe that they can tap it now if it is for 
DEFENSIVE measures only 

Webfora and the Onion Router (TOR) (U) 

(S SI REL TO USA, NLD) The web forum discussion was of greater interest The 

Dutch provided an overview of their data present ai ion tool (at a very high level). They 
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data, with other social network info, and trying to figure out good ways to mine the data 
that they have. 

(S. "SL REL TO USA. NLD) Questions the Dutch, had were based on our analytic 
tr ad ecraft.^^B noted that we use keywords to some extent, and outlined the division of 
effort between ^^^^^Jand sustained targeting, [f that partner engagement is of interest 
(from^^^l perspective, it is in that we want to track their activities on ^^^|and 
maximize their exploitation of that data),^^Jsuspects we can focus on tradecuaft and 
general analytic philosophy and build quite a bit of credibility that way. 

(S/VSI. REL TO U S A , N L D)^^| g ive a brief update on our efforts with Ton noting that 
the multi-national effort seemed the best avenue for a sustained capability at present and 
we are actively working our legal processes to make progress. 



ACTION ITEMS FROM 14 FEBRUARY 2013 MEETINGS ON SIGINT CYBER 
(These action items have also been sent separately) 

1) (S SI) CDO TAD and NTOC: Draft a cyber MOU for Dutch review 

—CDO SIGINT to inform DIRNSA that MOU will be drafted (DIRNSA and AIVD 
Director both informed; NTOC will draft MOU) 

2) (S SI) CDO SIGINT: Seek preview of public version of^^^^^|message and 

convey to th at having a preview in the future in time to alert Dutch 

CERTS would be ideal (done — not enough time to obtain preview for this round, but 
the idea for the future has been conveyed) 




4) (S "SI) CDO SIGINT: Will try to obtain updated version 
Dutch (done) 

5) (S ’SIi^^H Will share information, handles, etc, on hackers 

6}(S SI) CDO 'SIGINT: Will create Cyber forum on^^^^|: will forward Tutelage and 
Malware presentations, Webfora article, and agenda via (briefings sent, but 

awaiting list of which U.S. personnel to put in Cyber forum) 
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